Support has been upgraded!
The Support Forum is closed. Not to worry! Providing the top quality support you expect and we're known for will continue! We're not ending support, just changing where you submit requests. This will provide you with the best experience possible.
Premium Support
Have you purchased an addon for Connections such as one of our premium templates or extensions with a valid license and you need help?
Please open a Support Ticket in your user account.
Free Support
Are you using the free Connections plugin? Don't worry, you are still very important to us! We are still providing you with the same high quality support that we're known for.
Please open a new support topic in the WordPress support forums for Connections.
- This topic has 3 replies, 2 voices, and was last updated 12 years, 2 months ago by
Steven Zahm.
-
AuthorPosts
-
06/08/2014 at 7:50 pm #293264
Chris Cox
ParticipantI never noticed this before until I started to fort Knox the WP. On the dashboard on the right hand side it displays the server configuration. I understand that means a lot to you for debugging. But anything that pulls that information is a bad idea. Yes hackers can pull that info on their own, but they could go ninja with this plugin doing it. You might maybe try some kind of extension for when/if it’s needed.
06/09/2014 at 10:30 am #293268Steven Zahm
Keymaster@ Chris
Sorry, but I have to disagree if hackers are seeing the Dashboard page, well, lets say, it is way too late and extremely likely they know far more than the bit of harmless info shown in the widget. In order to even get to the code as it can not be loaded directly the hacker has to be logged in to WP and have to correct user capability. So basically three levels of core WP security features would have to be breached.
06/09/2014 at 10:54 am #293294Chris Cox
ParticipantWhat I’m saying is this. First the hacker has to find loop holes in any of the plugins. That in turn allows them to upload a file giving them the needed info. Which in turn they sell to other hackers where to find the information. And if any plugin pulls that information especially on a nonssl site can be swiped in the process of plugin > database / database > plugin. They don’t have to view the dashboard to get the information.
Hosts constantly update their servers to help with issues like that. But with the plugin pulling the info for them they know the minute it’s updated. And like I said with the plugin pulling the info they can simply pass through the plugin>database/database>plugin. They have no need for a file to remain on the server for the info, making it extremely hard to pinpoint the troublesome file.
06/21/2014 at 8:53 am #294655Steven Zahm
Keymaster@ Chris
(italics are quotes from your last reply, just for clarification, nothing more)
Sorry, still disagree. “And like I said with the plugin pulling the info they can simply pass through the plugin>database/database>plugin.” Where do you think this info is coming from? This info is supplied by WordPress/PHP. A plugin is not needed to hand serve up to the minute server config. The data Connections shows actually contains no server config info. Examples of server config being the Apache conf files, htaccess files, and maybe even php.ini files. There’s actually quite a few files beyond those for server config. If “the hacker has to find loop holes in any of the plugins”. The hacker would very likely already know far, far, more info than the few basics than are presented in the widget.
Many plugins far more popular than Connections show a whole heck of a lot more and in some cases do stuff that is able to alter the WordPress configuration. A few quick example off the top of my head…
WordPress SEO by Yoast includes a htaccess file editor.
Wordpress includes a plugin and theme editor.
Easy Digital Downloads has a screen chock-full of info.
BackupBuddy, now there system info tool that is of envy, details galore. One can even manipulate the db (check/repair) and crons.If it were best practice not to have this, trust me, it would not exist in Connections. But I have not read one article anywhere in the WP community that thinks this is a bad idea.
I really do thank you for pointing this out and why this concerns you. I do value constructive feedback and the time it takes to write it. It really is nice to have eyes looking at it from a different angle, so again, thanks!
-
AuthorPosts
You cannot reply to this support topic. Please open your own support topic.
